Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Microsoft patches critical Windows XP vulnerability

Microsoft still needs to patch two more vulnerabilities related to Stuxnet

Article comments

Microsoft has patched a critical Windows XP vulnerability that aided attacks based on the Stuxnet worm by letting attackers gain remote access through the operating system's print spooler service.

But there are still two vulnerabilities related to Stuxnet that Microsoft has not patched, according to Kaspersky Lab

The print spooler security bulletin is one of nine issued in Microsoft's monthly Patch Tuesday, and one of four rated as critical.

"The most dangerous vulnerability is the Print Spooler service impersonation issue," Symantec Security Response official Joshua Talbot writes in a statement regarding the Microsoft security updates. "This vulnerability has been identified by Symantec as one of the attack vectors built into the notorious Stuxnet threat, which targets industrial control systems. This is evidence the vulnerability is already being exploited in the wild."

The Stuxnet worm was discovered in July and was designed to steal industrial secrets, claiming Siemens as one of its publicly disclosed victims.

Microsoft patched a vulnerability related to Stuxnet last month but the print spooler vulnerability represents a new attack vector for the worm. It was reported to Microsoft by Kaspersky Lab and Symantec.

Microsoft patched critical Windows XP vulnerabilityKaspersky Lab says that it has "identified yet another zero-day vulnerability in Stuxnet's code, this time an Elevation of Privilege (EoP) vulnerability. The worm uses this to get complete control over the affected system. A second EoP vulnerability was identified by Microsoft personnel, and both vulnerabilities will be fixed in a security bulletin in the near future."

That means there are four vulnerabilities related to Stuxnet, and only two have been patched.

"The fact that Stuxnet uses four previously unidentified vulnerabilities makes the worm a real standout among malware," Kaspersky writes. "It's the first time we've come across a threat that contains so many 'surprises'."

The print spooler error fixed Tuesday affects a wide range of software including Windows 7, Windows Vista, Windows Server 2003, and Windows Server 2008. But it was only rated as "critical" for Windows XP.

"When a computer is configured to use a shared printer, a remote or local attacker can use this vulnerability to gain system-level access and add malicious code to any file in Windows' core directory where operating system files are stored," Talbot of Symantec writes. "System and configuration files in this directory often automatically execute. By overwriting one of these files, the attacker supplied code would automatically run instead of the legitimate file, resulting in the machine being completely compromised."

"This vulnerability allows for a great deal of stealth since no user interaction is required for an attacker to exploit it," Talbot continued. "Affected systems run the gamut, but Windows XP is the most vulnerable. An attacker has to be able to send a ‘print to file' command as well as other malicious instructions to the machine. XP most readily facilitates this by having a guest account with anonymous access enabled by default."

It's not unlikely that more vulnerabilitles related to Stuxnet are just waiting to be found, says Jason Miller, data and security team manager at Shavlik Technologies.

"Malware evolves," he says. "It's a big game of cat and mouse."In addition to the print spooler flaw, Microsoft patched a vulnerability in MPEG-4 codec.

"The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content," Microsoft said. "An attacker who successfully exploited this vulnerability could gain the same user rights as the local user."

The MPEG-4 security update is rated critical for various editions of Windows 7, Windows XP, Windows Vista and Windows Server.


More from Techworld

More relevant IT news


marge said: Im so confused have windows xp can i still getupdates

Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *